This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

What is going on if DNS packets from China get blocked?

Hi folks,


I read this in our weekly UTM9 report:

Most blocked source IP address is 42.120.221.11 (China), port 53 (DNS), 161.684 packets blocked.

Destination IP is the internet interface on the Sophos.

So what does that mean? Why are they sending that much packets?

Kind regards,


Stefan



This thread was automatically locked due to age.
Parents Reply
  • Probably not a DDOS as all packets came from the one IP.  Maybe a brute force attempt to poison your DNS cache - were all packets srcport="53" and dstport random?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
  • Nope, destination port was always 28106...

    Time Action Rule Interface IN Interface OUT Source MAC Destination MAC Source IP Destination IP Protocol Length TTL Source Port Destination Port
    2016:04:29-19:30:44 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:30:44 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:30:44 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:30:44 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:32:13 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:35:42 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:40:44 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:47:26 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:50:05 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:50:59 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:30:44 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:30:44 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:30:44 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:30:44 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:32:13 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:35:42 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:40:44 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:47:26 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:50:05 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106
    2016:04:29-19:50:59 drop 60001 eth4.231 124 00:1f:9f:xx:xx:xx 00:1a:8c:xx:xx:xx 42.120.221.11 192.168.254.2 17 0x20 113 53 28106